[exim] oddity with v4.2, ipfilter and remote v4.4

Top Page
Delete this message
Reply to this message
Author: V. T. Mueller, Continum
Date:  
To: exim-users
Subject: [exim] oddity with v4.2, ipfilter and remote v4.4
Hello,


On a rather central mail server we´ve been running exim 4.20 for over a
year now with exactly zero problems. All the time that hosts' ipfilter
rules regarding SMTP have been set to:

# SMTP
pass in on lan0 proto tcp from any to any port = 25 flags S/SA keep state
pass out on lan0 proto tcp from any to any port = 25 flags S/SA keep state
pass in on lan0 proto tcp from any port = 25 to any flags S/SA keep state
pass out on lan0 proto tcp from any port = 25 to any flags S/SA keep state

One remote site to which we regularly relay updated to v4.40 a few days
ago. That resulted in a loss of SMTP communication capability since our
ipfilter then did:

[snip] lan0 @0:1 b <local>,54429 -> <remote>,25 PR tcp len 20 1500 -AP OUT

This is easily worked around, but it also leaves me somewhat scratching
my head. There is no other host triggering that problem here (I counted
2k+ different remote SMTP hops so far in August), and according to our
logs there never ever has been one. The only change I am aware of is that
the remote host now runs 4.40 but did run 4.31 days ago.

Have we been lucky fools with wrong filter setups? Is that remote hosts'
tcp stack garbage? Is this a general 4.2<>4.4 issue? Is the earth flat?

TIA,

Volker

--
V. T. Mueller
Continum AG
Wentzinger Strasse 7a
79106 Freiburg i. Br.
http://www.continum.net
Tel.: +49 761 479409 70
Fax.: +49 761 479409 33
Mail: v.t.mueller@???